Delivery Tier Users
Bloomreach Experience Manager's delivery tier includes four default users:
- configuser
- liveuser
- previewuser
- sitewriter
configuser
The configuser account requires read access to nearly all nodes in the repository. This user does not require write permissions.
liveuser
The liveuser account is used to render live content. This user should not have write access to any node type.
previewuser
The previewuser account is used to render preview content. The Experience manager preview uses this user, sometimes in combination with the CMS editor or author account. For details, see Experience Manager Preview With Security Delegation. This user should not have write access to any node type.
sitewriter
The sitewriter account is used to persist changes to the repository, such as storing form data or performing workflow actions on documents. By default, sitewriter has write access only to form data. To use the HST workflow manager (WorkflowPersistenceManager), you must grant sitewriter additional permissions. See Configure Permissions when using Workflow in the Delivery Tier for configuration details.
Optional Separate Binaries User
The binaries session pool manages JCR sessions for the binaries servlet when a request does not already have an HstRequestContext. If an HstRequestContext exists, the session returned by HstRequestContext#getSession is used. Typically, this is the liveuser for live content and the previewuser for preview content (such as in Experience manager preview). By default, the binaries user is the same as the liveuser. To use a different user, set the binaries.repository.user.name property in your hst-config.properties file.
Passwords
Starting with Bloomreach Experience Manager 10.0, you can leave the password for all default site users empty in hst-config.properties, or omit the configuration entirely. The users in the repository are configured with:
hipposys:passkey: jvm://
When the HST site web application and the repository run in the same JVM (the standard setup), the HST can obtain a JCR session using only the user name, without a password. The following JVM-enabled users are configured by default:
- configuser
- liveuser
- previewuser
- sitewriter
To use a JVM-enabled user without a password:
-
Ensure the user in the repository has
hipposys:passkey = jvm://:/hippo:configuration: /hippo:users: /configuser: hipposys:passkey: jvm:// /liveuser: hipposys:passkey: jvm:// /previewuser: hipposys:passkey: jvm:// /sitewriter: hipposys:passkey: jvm:// -
In
hst-config.properties, remove the password for each user or leave it empty. For best results, remove all user-related properties such asdefault.repository.user.nameanddefault.repository.password.Hint: Remove all user-related properties from
hst-config.propertieswhen using JVM-enabled users.
Optional
If you use JVM-enabled site users, you can remove the hipposys:password property from each user. This is recommended for production environments. Retain the password only if you need to log in with a site user through the repository servlet at /repository.
Advantages of JVM-Enabled Site Users
JVM-enabled site users eliminate the need to store passwords for site users in external files such as hst-config.properties. If a site user's password changes in the repository, you do not need to update passwords on every cluster node. Additionally, you do not need to manage different passwords for site users across environments.